Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.3
CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure …

Fix: 2.2.4+
Fix from $1,600 2026-06-23
Debian Linux HIGH 7.8
CVE-2026-41082

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Fix: 2.5.1+
Fix from $1,950 2026-04-16
Debian Linux HIGH 7.5
CVE-2026-1940

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsiz…

Fix: 1.28.1+
Fix from $1,950 2026-03-23
Debian Linux HIGH 7.8
CVE-2025-63261

AWStats 8.0 is vulnerable to Command Injection via the open function

No fix yet
Fix from $1,950 2026-03-20
Dpkg HIGH 7.5
CVE-2026-2219

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream whe…

Fix: 1.21.23 / 1.22.22+
Fix from $1,950 2026-03-07
Debian Linux HIGH 7.8
CVE-2026-25506

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vul…

Fix: 0.5.18+
Fix from $1,950 2026-02-10
Debian Linux MEDIUM 5.9
CVE-2025-64098

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.…

Fix: 2.6.11 / 3.3.1+
Fix from $1,600 2026-02-03
Debian Linux CRITICAL 9.8
CVE-2025-62799

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.…

Fix: 2.6.11 / 3.3.1+
Fix from $2,300 2026-02-03
Debian Linux HIGH 7.5
CVE-2025-62602

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.…

Fix: 2.6.11 / 3.3.1+
Fix from $1,950 2026-02-03
Debian Linux HIGH 7.5
CVE-2025-62603

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is …

Fix: 2.6.11 / 3.3.1+
Fix from $1,950 2026-02-03
Debian Linux HIGH 7.5
CVE-2025-62600

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14…

Fix: 2.6.11 / 3.3.1+
Fix from $1,950 2026-02-03
Debian Linux HIGH 7.5
CVE-2025-62599

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14…

Fix: 2.6.11 / 3.3.1+
Fix from $1,950 2026-02-03
Debian Linux HIGH 7.5
CVE-2026-25061

tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a lengt…

Fix: after 1.6.1
Fix from $1,950 2026-01-29
Debian Linux HIGH 7.8
CVE-2026-24765

PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involvi…

Fix: 8.5.52 / 9.6.33+
Fix from $1,950 2026-01-27
Debian Linux CRITICAL 9.8
CVE-2025-68670

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im…

Fix: 0.10.5+
Fix from $2,300 2026-01-27
Debian Linux CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Fix: after 2.7
Fix from $2,300 2026-01-21
Debian Linux CRITICAL 9.8
CVE-2025-68615EPSS 44%

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd …

Fix: 5.9.5+
Fix from $2,300 2025-12-23
Debian Linux MEDIUM 6.1
CVE-2025-63498

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

Patch available
Fix from $1,600 2025-11-24
Debian Linux HIGH 7.8
CVE-2025-64512

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107…

Fix: 2025-11-07+
Fix from $1,950 2025-11-10
Debian Linux HIGH 7.3
CVE-2025-62230

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data struc…

Fix: 21.1.19+
Fix from $1,950 2025-10-30
Debian Linux HIGH 7.3
CVE-2025-62231

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause a…

Fix: 21.1.19+
Fix from $1,950 2025-10-30
Debian Linux HIGH 7.8
CVE-2025-10934

GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2025-10-29
Debian Linux HIGH 7.8
CVE-2025-10921

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2025-10-29
Debian Linux HIGH 7.8
CVE-2025-10922

GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2025-10-29
Devscripts CRITICAL 9.8
CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to …

Mitigation only
Fix from $2,300 2025-08-01
Dpkg HIGH 8.2
CVE-2025-6297

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…

Fix: 1.22.21+
Fix from $1,950 2025-07-01
Yubiserver CRITICAL 9.8
CVE-2015-0842

yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

Mitigation only
Fix from $2,300 2025-06-26
Yubiserver CRITICAL 9.8
CVE-2015-0843

yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.

Mitigation only
Fix from $2,300 2025-06-26
Pdns CRITICAL 9.8
CVE-2014-7210

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of p…

Fix: 3.3.1-1+
Fix from $2,300 2025-06-26
Matplotlib MEDIUM 5.6
CVE-2013-1424

Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.

Fix: 1.4.2-3.1+
Fix from $1,600 2025-06-26